Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv9q-5762-xc65

Опубликовано: 17 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

EPSS

Процентиль: 20%
0.00279
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-669

Связанные уязвимости

CVSS3: 6.4
ubuntu
10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

CVSS3: 6.4
nvd
10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

CVSS3: 6.4
debian
10 дней назад

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa ...

EPSS

Процентиль: 20%
0.00279
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-669